← Back to home
Comparison · Collab

BookStack vs Document360

A side-by-side editorial comparison of BookStack and Document360 — release velocity, themes, recent moves, and the top alternatives to consider.

BookStack vs Document360: at a glance

FeatureBookStackDocument360
SectorCollabCollab
Velocity score5.06.3
Sparks · 30d01
Top themesself-hosted, security-releases, permissions, documentationapi, oauth, mcp, knowledge base
Last editorial update20d ago1d ago
WebsiteVisit →

What is BookStack?

BookStack's release stream is mostly security patches with feature drops in between.

Four of BookStack's last six releases are security releases. The newest closes five separate issues at once: external authentication could match the wrong user where IDs differ only by casing or accents, the login form leaked user existence through timing, exported content could load interactive content over file links, API errors exposed debug detail by default, and the default PDF renderer could probe files on the host. The one feature release, v26.05, added a page contents view in the editor, tag browsing API endpoints, a dedicated revision-viewing permission, in-UI MFA reset and new image and CSP controls.

Read the full BookStack trajectory →

What is Document360?

Document360 rebuilt its API for agents; now it's turning the AI inward on authoring.

Monthly point releases on a steady 12.x line, each a themed bundle rather than a fix list. The last three releases rebuilt the developer-facing surface: an interactive API reference with an in-page Try It! console, a ground-up API v3 with OAuth 2.0 and scoped keys, and a Widget 2.0 embedding architecture now rolling out with a migration deadline. Around that, Eddy AI and the MCP server have been gaining governance controls — reader-group restrictions, workflow permissions, usage analytics — more often than new capabilities.

Read the full Document360 trajectory →

BookStack vs Document360: editorial side-by-side

B
BookStack
COLLAB
5.0

BookStack's release stream is mostly security patches with feature drops in between.

◆ Current state

Four of BookStack's last six releases are security releases. The newest closes five separate issues at once: external authentication could match the wrong user where IDs differ only by casing or accents, the login form leaked user existence through timing, exported content could load interactive content over file links, API errors exposed debug detail by default, and the default PDF renderer could probe files on the host. The one feature release, v26.05, added a page contents view in the editor, tag browsing API endpoints, a dedicated revision-viewing permission, in-UI MFA reset and new image and CSP controls.

◆ Where it's heading

Cadence is set by responsible disclosures — a named researcher credited in nearly every patch — and the feature work leans the same way, toward finer permissions and content security controls. For a self-hosted wiki that users routinely expose publicly, hardening is the roadmap, with quarterly feature releases sitting between patch runs.

◆ Prediction

Expect another patch on the 26.05 line next. The permission and CSP work visible in v26.05 is the thread the following minor most plausibly continues, though the entries give no signal on timing.

D6.3

Document360 rebuilt its API for agents; now it's turning the AI inward on authoring.

◆ Current state

Monthly point releases on a steady 12.x line, each a themed bundle rather than a fix list. The last three releases rebuilt the developer-facing surface: an interactive API reference with an in-page Try It! console, a ground-up API v3 with OAuth 2.0 and scoped keys, and a Widget 2.0 embedding architecture now rolling out with a migration deadline. Around that, Eddy AI and the MCP server have been gaining governance controls — reader-group restrictions, workflow permissions, usage analytics — more often than new capabilities.

◆ Where it's heading

Two threads run through the year. One makes the knowledge base machine-readable and machine-writable: MCP server, automatic llms.txt, open-an-article-in-ChatGPT-or-Claude, then API v3. The other fences that access with admin controls before enterprise buyers have to ask. The newest release turns the AI inward for the first time — the redesigned Publish dialog puts suggestions and validation in the author's path rather than the reader's, which is a different customer for the same capability.

◆ Prediction

The AI suggestions now sitting in the Publish dialog are the obvious candidate to move into the editor itself, and the advanced v3 endpoints sold as an add-on look like the seed of a higher API tier. The Widget 2.0 forced migration is the near-term execution risk, since it puts required technical work on existing customers to a fixed timeline.

Alternatives to BookStack and Document360

Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either BookStack or Document360.

See all BookStack alternatives → · See all Document360 alternatives →

Recent activity from BookStack and Document360

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 2d agoDocument360Publish dialog folds in AI suggestions and pre-publish checks
  2. 9d agoDocument360API v3 rebuild adds OAuth 2.0 and scoped API keys
  3. 16d agoDocument360Interactive API reference with a rebuilt Try It! console
  4. 21d agoBookStackSecurity release fixes five issues including auth matching
  5. 1mo agoDocument360Find and replace spans variables, snippets, and links
  6. 1mo agoBookStackURL filtering, redirects and permission checks hardened
  7. 1mo agoDocument360Native Mermaid diagrams and automatic llms.txt generation
  8. 2mo agoDocument360MCP server gains publishing and workflow controls
  9. 2mo agoBookStackAttachment metadata leak and file:// export risk closed
  10. 2mo agoBookStackv26.05 adds page contents view, tag API and revision permissions
  11. 2mo agoBookStackRate limiting added to MFA verification routes
  12. 3mo agoBookStackAttachment permission and webhook URL validation fixes

Frequently asked questions

What is the difference between BookStack and Document360?

They serve adjacent needs but don't currently overlap on shipped themes. Document360 is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is BookStack better than Document360?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Document360 is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.

What are the best alternatives to BookStack?

Top BookStack alternatives in Collab are ranked by recent ship velocity. Browse the "BookStack alternatives" section above for the current picks, or visit /alternatives/bookstack for the full list with editorial commentary on each.

What are the best alternatives to Document360?

Top Document360 alternatives in Collab are ranked by recent ship velocity. Browse the "Document360 alternatives" section above for the current picks, or visit /alternatives/document360 for the full list with editorial commentary on each.